GHSA-4v58-74mf-rjx3
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
Quick fix
GHSA-4v58-74mf-rjx3 — github.com/rabbitmq/amqp091-go: upgrade to the fixed version with the command below.
go get github.com/rabbitmq/amqp091-go@v1.13.0Details
**Summary** A vulnerability in the readField function allows a malicious or compromised AMQP server to trigger an unhandled runtime panic in the client application, leading to an immediate crash of the entire process.
**Details** When parsing incoming AMQP frames, the `readField` function processes byte-array fields (type tag `'x'`) by reading a 32-bit big-endian integer to determine the length of the data payload.
```go // read.go:253-263 case 'x': var len int32 if err = binary.Read(r, binary.BigEndian, &len); err != nil { return nil, err } value := make([]byte, len) // PANICS if len < 0 ```
If a server transmits a length value of `0xFFFFFFFF`, it is interpreted by the client as a signed 32-bit integer with a value of `-1`. Passing a negative integer to Go's built-in make() function for slice allocation triggers an unrecoverable runtime panic (panic: len out of range).
Because the reader goroutine handles network I/O without an explicit recover() wrapper, this panic propagates up to the runtime root, abruptly terminating the host application.
**Attack Vector / Exploitation Scenario** An attacker capable of spoofing, compromising, or controlling an AMQP broker can exploit this flaw during two primary phases:
1. Connection Establishment: Sending a malicious connection.start handshake frame containing server-properties with an 'x' type field assigned a negative length. 2. Message Delivery: Delivering a message payload where the header table contains a malformed field matching the criteria above.
**Impact** Availability: High. A single malformed frame can reliably crash the client process, resulting in a persistent Denial of Service (DoS) if the client automatically reconnects and receives the same payload.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.13.0go get github.com/rabbitmq/amqp091-go@v1.13.0References
- https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-4v58-74mf-rjx3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-77412[ADVISORY]
- https://github.com/rabbitmq/amqp091-go/pull/344[WEB]
- https://github.com/rabbitmq/amqp091-go/commit/669b42bf7b1db76bc6d4973e3634247f680accbf[WEB]
- https://github.com/rabbitmq/amqp091-go[PACKAGE]
- https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0[WEB]